CNNVD-202506-3110 Information

CNNVD ID

CNNVD-202506-3110

CVE-2025-53073

  • CNNVD Published: 2025-06-24

Description (Chinese)

Sentry是Sentry开源的一个面向开发人员的错误跟踪和性能监控平台。 Sentry 25.1.0至25.5.1版本存在安全漏洞,该漏洞源于认证的攻击者可访问项目问题端点并执行未授权操作。

Description (English)

Sentry is a development-oriented bug-tracking and performance-monitoring platform that is open to Sentry. There is a security loophole in releases 25.1 to 25.5.1 from certified assailants to access project problem points and perform unauthorized operations.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Seowon Intech

Published

2025-06-24

Last Modified

2026-02-24

References

https://github.com/nikolas-ch/CVEs/tree/main/Sentry_Version%3E%3D25.1.0 https://github.com/getsentry/self-hosted/releases https://github.com/nikolas-ch/CVEs/blob/main/Sentry_Version%3E%3D25.1.0/Sentry_%3E%3D25.1.0_WeakAuthorizationControl.txt https://access.redhat.com/security/cve/cve-2025-53073

Patch

https://github.com/getsentry/self-hosted/releases

Share on: